Beveiligingsadvies

CVE-2022-2025

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-09-23 15:06:54
Laatst bijgewerkt 2025-05-22 19:59:54
Toegewezen door INCIBE
CVSS-score 9.8
Status PUBLISHED

Beschrijving

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.